Code Injection in Flowise - #VU146559

 

Code Injection in Flowise - #VU146559

Published: September 1, 2026


Vulnerability identifier: #VU146559
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal network resources and disclose sensitive information.

The vulnerability exists due to improper sandbox restrictions in the NodeVM custom JavaScript function environment when E2B sandbox is not configured and custom JavaScript functions can require overly permissive dependencies. A remote user can use allowed browser automation or database libraries to access internal network resources and disclose sensitive information.

The issue affects the fallback NodeVM execution path when E2B sandbox is not configured.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins